AWS Lambda Serverless Development
Design, build, deploy, and debug serverless applications with AWS serverless services. This skill provides access to serverless development guidance through the AWS Serverless MCP Server, helping you to build production-ready serverless applications with best practices built-in.
Use SAM CLI for project initialization and deployment, Lambda Web Adapter for web applications, or Event Source Mappings for event-driven architectures. AWS handles infrastructure provisioning, scaling, and monitoring automatically.
Key capabilities:
- SAM CLI Integration: Initialize, build, deploy, and test serverless applications
- Web Application Deployment: Deploy full-stack applications with Lambda Web Adapter
- Event Source Mappings: Configure Lambda triggers for DynamoDB, Kinesis, SQS, Kafka
- Lambda durable functions: Resilient multi-step applications with checkpointing — see the durable-functions skill for guidance
- Schema Management: Type-safe EventBridge integration with schema registry
- Observability: CloudWatch logs, metrics, and X-Ray tracing
- Performance Optimization: Right-sizing, cost optimization, and troubleshooting
When to Load Reference Files
Load the appropriate reference file based on what the user is working on:
- Getting started, what to build, project type decision, or working with existing projects -> see references/getting-started.md
- SAM, CDK, deployment, IaC templates, CDK constructs, or CI/CD pipelines -> see the aws-serverless-deployment skill (separate skill in this plugin)
- Web app deployment, Lambda Web Adapter, API endpoints, CORS, authentication, custom domains, or sam local start-api -> see references/web-app-deployment.md
- Event sources, DynamoDB Streams, Kinesis, SQS, Kafka, S3 notifications, or SNS -> see references/event-sources.md
- EventBridge, event bus, event patterns, event design, Pipes, or schema registry -> see references/event-driven-architecture.md
- Durable functions, checkpointing, replay model, saga pattern, or long-running Lambda workflows -> see the durable-functions skill (separate skill in this plugin with full SDK reference, testing, and deployment guides)
- Orchestration, workflows, or Durable Functions vs Step Functions -> see references/orchestration-and-workflows.md
- Step Functions, ASL, state machines, JSONata, Distributed Map, or SDK integrations -> see references/step-functions.md
- Step Functions testing, TestState API, mocking service integrations, or state machine unit tests -> see references/step-functions-testing.md
- Observability, logging, tracing, metrics, alarms, or dashboards -> see references/observability.md
- Optimization, cold starts, memory tuning, cost, or streaming -> see references/optimization.md
- Powertools, idempotency, feature flags, parameters, parser, batch processing, or data masking -> see references/powertools.md
- Troubleshooting, errors, debugging, or deployment failures -> see references/troubleshooting.md
Best Practices
Project Setup
- Do: Use
sam_init or cdk init with an appropriate template for your use case
- Do: Set global defaults for timeout, memory, runtime, and tracing (
Globals in SAM, construct props in CDK)
- Do: Use AWS Lambda Powertools for structured logging, tracing, metrics (EMF), idempotency, and batch processing — available for Python, TypeScript, Java, and .NET
- Don't: Copy-paste templates from the internet without understanding the resource configuration
- Don't: Use the same memory and timeout values for all functions regardless of workload
Security
- Do: Follow least-privilege IAM policies scoped to specific resources and actions
- Do: Use
secure_esm_* tools to generate correct IAM policies for event source mappings
- Do: Store secrets in AWS Secrets Manager or SSM Parameter Store, never in environment variables
- Do: Use VPC endpoints instead of NAT Gateways for AWS service access when possible
- Do: Enable Amazon GuardDuty Lambda Protection to monitor function network activity for threats (cryptocurrency mining, data exfiltration, C2 callbacks)
- Don't: Use wildcard (
*) resource ARNs or actions in IAM policies
- Don't: Hardcode credentials or secrets in application code or templates
- Don't: Store user data or sensitive information in module-level variables — execution environments can be reused across different callers
Idempotency
- Do: Write idempotent function code — Lambda delivers events at least once, so duplicate invocations must be safe
- Do: Use the AWS Lambda Powertools Idempotency utility (backed by DynamoDB) for critical operations
- Do: Validate and deduplicate events at the start of the handler before performing side effects
- Don't: Assume an event will only ever be processed once
Packaging & Dependencies
- Do: Remember that attaching a public or cross-account Lambda layer requires
lambda:GetLayerVersion on that layer ARN for the DEPLOYING identity (not just the function role). Restricted CI/sandbox roles frequently lack this and fail at CreateFunction with AccessDeniedException.
- Do: In locked-down environments, vendor dependencies into the deployment package (e.g.
pip install -r requirements.txt -t <build_dir>, then zip deps + source together) instead of referencing a foreign-account layer ARN — the package becomes self-contained and independent of the deployer's cross-account permissions. (Alternatively, copy the layer into the target account.)
- Do:
boto3/botocore are already in the managed runtime — don't vendor them (wasted size); vendor only the extra libs (e.g. Powertools, jsonschema, PyYAML).
- Do: When you bundle non-code assets (JSON schemas, config, templates) into the package, resolve their path at runtime from a known base (e.g. an env var pointing at
/var/task/<dir>, or os.path.dirname(__file__)), not from a build-time relative path that won't exist in the runtime layout.
- Don't: Assume a layer that works interactively will deploy in CI — the deploy principal's permissions differ from yours.
For topic-specific best practices, see the dedicated guide files in the reference table above.
Lambda Limits Quick Reference
Limits that developers commonly hit:
| Resource |
Limit |
| Function timeout |
900 seconds (15 minutes) |
| Memory |
128 MB – 10,240 MB |
| 1 vCPU equivalent |
1,769 MB memory |
| Synchronous payload (request + response) |
6 MB each |
| Async invocation payload |
1 MB |
| Streamed response |
200 MB |
| Deployment package (.zip, uncompressed) |
250 MB |
| Deployment package (.zip upload, compressed) |
50 MB |
| Container image |
10 GB |
| Layers per function |
5 |
| Environment variables (aggregate) |
4 KB |
/tmp ephemeral storage |
512 MB – 10,240 MB |
| Account concurrent executions (default) |
1,000 (requestable increase) |
| Burst scaling rate |
1,000 new executions per 10 seconds |
Check Service Quotas for your account limits: aws lambda get-account-settings
Troubleshooting Quick Reference
| Error |
Cause |
Solution |
Build Failed |
Missing dependencies |
Run sam_build with use_container: true |
Stack is in ROLLBACK_COMPLETE |
Previous deploy failed |
Delete stack with aws cloudformation delete-stack, redeploy |
IteratorAge increasing |
Stream consumer falling behind |
Increase ParallelizationFactor and BatchSize. Use esm_optimize |
| EventBridge events silently dropped |
No DLQ, retries exhausted |
Add RetryPolicy + DeadLetterConfig to rule target |
| Step Functions failing silently |
No retry on Task state |
Add Retry with Lambda.ServiceException, Lambda.AWSLambdaException |
| Durable Function not resuming |
Missing IAM permissions |
Add lambda:CheckpointDurableExecution and lambda:GetDurableExecutionState — see durable-functions skill |
AccessDeniedException: ... not authorized to perform: lambda:GetLayerVersion on CreateFunction/UpdateFunctionConfiguration |
Attaching a public/cross-account layer (e.g. the AWS-published Powertools layer, owned by another account) but the deploying identity lacks lambda:GetLayerVersion on it |
Grant the deployer lambda:GetLayerVersion on the layer ARN, OR vendor the dependency into the deployment package and drop the layers reference (works in locked-down CI/sandbox roles). See Packaging & Dependencies below |
For detailed troubleshooting, see references/troubleshooting.md.
Configuration
AWS CLI Setup
This skill requires that AWS credentials are configured on the host machine:
Verify access: Run aws sts get-caller-identity to confirm credentials are valid
SAM CLI Setup
- Install SAM CLI: Follow the SAM CLI installation guide
- Verify: Run
sam --version
Container Runtime Setup
- Install a Docker compatible container runtime: Required for
sam_local_invoke and container-based builds
- Verify: Use an appropriate command such as
docker --version or finch --version
MCP Server Configuration
Write access is enabled by default. The plugin ships with --allow-write in .mcp.json, so the MCP server can create projects, generate IaC, and deploy on behalf of the user.
Access to sensitive data (like Lambda and API Gateway logs) is not enabled by default. To grant it, add --allow-sensitive-data-access to .mcp.json.
SAM Template Validation Hook
This plugin includes a PostToolUse hook that runs sam validate automatically after any edit to template.yaml or template.yml. If validation fails, the error is returned as a system message so you can fix it immediately. The hook requires SAM CLI and jq to be installed; if either is missing, validation is skipped with a system message. Users can disable it via /hooks.
Verify: Run jq --version
Language selection
Default: TypeScript
Override syntax:
- "use Python" → Generate Python code
- "use JavaScript" → Generate JavaScript code
When not specified, ALWAYS use TypeScript
IaC framework selection
Default: CDK
Override syntax:
- "use CloudFormation" → Generate YAML templates
- "use SAM" → Generate YAML templates
When not specified, ALWAYS use CDK
Serverless MCP Server Unavailable
- Inform user: "AWS Serverless MCP not responding"
- Ask: "Proceed without MCP support?"
- DO NOT continue without user confirmation
Resources
1---2name: aws-lambda3description: Design, build, deploy, test, and debug serverless applications with AWS Lambda. Triggers on phrases like: Lambda function, event source, serverless application, API Gateway, EventBridge, Step Functions, serverless API, event-driven architecture, Lambda trigger. For deploying non-serverless apps to AWS, use deploy-on-aws plugin instead.4---56# AWS Lambda Serverless Development78Design, build, deploy, and debug serverless applications with AWS serverless services. This skill provides access to serverless development guidance through the AWS Serverless MCP Server, helping you to build production-ready serverless applications with best practices built-in.910Use SAM CLI for project initialization and deployment, Lambda Web Adapter for web applications, or Event Source Mappings for event-driven architectures. AWS handles infrastructure provisioning, scaling, and monitoring automatically.1112**Key capabilities:**1314- **SAM CLI Integration**: Initialize, build, deploy, and test serverless applications15- **Web Application Deployment**: Deploy full-stack applications with Lambda Web Adapter16- **Event Source Mappings**: Configure Lambda triggers for DynamoDB, Kinesis, SQS, Kafka17- **Lambda durable functions**: Resilient multi-step applications with checkpointing — see the [durable-functions skill](../aws-lambda-durable-functions/) for guidance18- **Schema Management**: Type-safe EventBridge integration with schema registry19- **Observability**: CloudWatch logs, metrics, and X-Ray tracing20- **Performance Optimization**: Right-sizing, cost optimization, and troubleshooting2122## When to Load Reference Files2324Load the appropriate reference file based on what the user is working on:2526- **Getting started**, **what to build**, **project type decision**, or **working with existing projects** -> see [references/getting-started.md](references/getting-started.md)27- **SAM**, **CDK**, **deployment**, **IaC templates**, **CDK constructs**, or **CI/CD pipelines** -> see the [aws-serverless-deployment skill](../aws-serverless-deployment/) (separate skill in this plugin)28- **Web app deployment**, **Lambda Web Adapter**, **API endpoints**, **CORS**, **authentication**, **custom domains**, or **sam local start-api** -> see [references/web-app-deployment.md](references/web-app-deployment.md)29- **Event sources**, **DynamoDB Streams**, **Kinesis**, **SQS**, **Kafka**, **S3 notifications**, or **SNS** -> see [references/event-sources.md](references/event-sources.md)30- **EventBridge**, **event bus**, **event patterns**, **event design**, **Pipes**, or **schema registry** -> see [references/event-driven-architecture.md](references/event-driven-architecture.md)31- **Durable functions**, **checkpointing**, **replay model**, **saga pattern**, or **long-running Lambda workflows** -> see the [durable-functions skill](../aws-lambda-durable-functions/) (separate skill in this plugin with full SDK reference, testing, and deployment guides)32- **Orchestration**, **workflows**, or **Durable Functions vs Step Functions** -> see [references/orchestration-and-workflows.md](references/orchestration-and-workflows.md)33- **Step Functions**, **ASL**, **state machines**, **JSONata**, **Distributed Map**, or **SDK integrations** -> see [references/step-functions.md](references/step-functions.md)34- **Step Functions testing**, **TestState API**, **mocking service integrations**, or **state machine unit tests** -> see [references/step-functions-testing.md](references/step-functions-testing.md)35- **Observability**, **logging**, **tracing**, **metrics**, **alarms**, or **dashboards** -> see [references/observability.md](references/observability.md)36- **Optimization**, **cold starts**, **memory tuning**, **cost**, or **streaming** -> see [references/optimization.md](references/optimization.md)37- **Powertools**, **idempotency**, **feature flags**, **parameters**, **parser**, **batch processing**, or **data masking** -> see [references/powertools.md](references/powertools.md)38- **Troubleshooting**, **errors**, **debugging**, or **deployment failures** -> see [references/troubleshooting.md](references/troubleshooting.md)3940## Best Practices4142### Project Setup4344- Do: Use `sam_init` or `cdk init` with an appropriate template for your use case45- Do: Set global defaults for timeout, memory, runtime, and tracing (`Globals` in SAM, construct props in CDK)46- Do: Use AWS Lambda Powertools for structured logging, tracing, metrics (EMF), idempotency, and batch processing — available for Python, TypeScript, Java, and .NET47- Don't: Copy-paste templates from the internet without understanding the resource configuration48- Don't: Use the same memory and timeout values for all functions regardless of workload4950### Security5152- Do: Follow least-privilege IAM policies scoped to specific resources and actions53- Do: Use `secure_esm_*` tools to generate correct IAM policies for event source mappings54- Do: Store secrets in AWS Secrets Manager or SSM Parameter Store, never in environment variables55- Do: Use VPC endpoints instead of NAT Gateways for AWS service access when possible56- Do: Enable Amazon GuardDuty Lambda Protection to monitor function network activity for threats (cryptocurrency mining, data exfiltration, C2 callbacks)57- Don't: Use wildcard (`*`) resource ARNs or actions in IAM policies58- Don't: Hardcode credentials or secrets in application code or templates59- Don't: Store user data or sensitive information in module-level variables — execution environments can be reused across different callers6061### Idempotency6263- Do: Write idempotent function code — Lambda delivers events **at least once**, so duplicate invocations must be safe64- Do: Use the AWS Lambda Powertools Idempotency utility (backed by DynamoDB) for critical operations65- Do: Validate and deduplicate events at the start of the handler before performing side effects66- Don't: Assume an event will only ever be processed once6768### Packaging & Dependencies6970- Do: Remember that **attaching a public or cross-account Lambda layer requires `lambda:GetLayerVersion` on that layer ARN for the DEPLOYING identity** (not just the function role). Restricted CI/sandbox roles frequently lack this and fail at `CreateFunction` with `AccessDeniedException`.71- Do: In locked-down environments, **vendor dependencies into the deployment package** (e.g. `pip install -r requirements.txt -t <build_dir>`, then zip deps + source together) instead of referencing a foreign-account layer ARN — the package becomes self-contained and independent of the deployer's cross-account permissions. (Alternatively, copy the layer into the target account.)72- Do: `boto3`/`botocore` are already in the managed runtime — don't vendor them (wasted size); vendor only the extra libs (e.g. Powertools, jsonschema, PyYAML).73- Do: When you bundle non-code **assets** (JSON schemas, config, templates) into the package, resolve their path at runtime from a known base (e.g. an env var pointing at `/var/task/<dir>`, or `os.path.dirname(__file__)`), not from a build-time relative path that won't exist in the runtime layout.74- Don't: Assume a layer that works interactively will deploy in CI — the deploy principal's permissions differ from yours.7576For topic-specific best practices, see the dedicated guide files in the reference table above.7778## Lambda Limits Quick Reference7980Limits that developers commonly hit:8182| Resource | Limit |83| -------------------------------------------- | ----------------------------------- |84| Function timeout | 900 seconds (15 minutes) |85| Memory | 128 MB – 10,240 MB |86| 1 vCPU equivalent | 1,769 MB memory |87| Synchronous payload (request + response) | 6 MB each |88| Async invocation payload | 1 MB |89| Streamed response | 200 MB |90| Deployment package (.zip, uncompressed) | 250 MB |91| Deployment package (.zip upload, compressed) | 50 MB |92| Container image | 10 GB |93| Layers per function | 5 |94| Environment variables (aggregate) | 4 KB |95| `/tmp` ephemeral storage | 512 MB – 10,240 MB |96| Account concurrent executions (default) | 1,000 (requestable increase) |97| Burst scaling rate | 1,000 new executions per 10 seconds |9899Check Service Quotas for your account limits: `aws lambda get-account-settings`100101## Troubleshooting Quick Reference102103| Error | Cause | Solution |104| ----------------------------------- | ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------- |105| `Build Failed` | Missing dependencies | Run `sam_build` with `use_container: true` |106| `Stack is in ROLLBACK_COMPLETE` | Previous deploy failed | Delete stack with `aws cloudformation delete-stack`, redeploy |107| `IteratorAge` increasing | Stream consumer falling behind | Increase `ParallelizationFactor` and `BatchSize`. Use `esm_optimize` |108| EventBridge events silently dropped | No DLQ, retries exhausted | Add `RetryPolicy` + `DeadLetterConfig` to rule target |109| Step Functions failing silently | No retry on Task state | Add `Retry` with `Lambda.ServiceException`, `Lambda.AWSLambdaException` |110| Durable Function not resuming | Missing IAM permissions | Add `lambda:CheckpointDurableExecution` and `lambda:GetDurableExecutionState` — see [durable-functions skill](../aws-lambda-durable-functions/) |111| `AccessDeniedException: ... not authorized to perform: lambda:GetLayerVersion` on `CreateFunction`/`UpdateFunctionConfiguration` | Attaching a **public/cross-account layer** (e.g. the AWS-published Powertools layer, owned by another account) but the **deploying identity** lacks `lambda:GetLayerVersion` on it | Grant the deployer `lambda:GetLayerVersion` on the layer ARN, OR **vendor the dependency into the deployment package** and drop the `layers` reference (works in locked-down CI/sandbox roles). See Packaging & Dependencies below |112113For detailed troubleshooting, see [references/troubleshooting.md](references/troubleshooting.md).114115## Configuration116117### AWS CLI Setup118119This skill requires that AWS credentials are configured on the host machine:120121**Verify access**: Run `aws sts get-caller-identity` to confirm credentials are valid122123### SAM CLI Setup1241251. **Install SAM CLI**: Follow the [SAM CLI installation guide](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/install-sam-cli.html)1262. **Verify**: Run `sam --version`127128### Container Runtime Setup1291301. **Install a Docker compatible container runtime**: Required for `sam_local_invoke` and container-based builds1312. **Verify**: Use an appropriate command such as `docker --version` or `finch --version`132133### MCP Server Configuration134135**Write access is enabled by default.** The plugin ships with `--allow-write` in `.mcp.json`, so the MCP server can create projects, generate IaC, and deploy on behalf of the user.136137Access to sensitive data (like Lambda and API Gateway logs) is **not** enabled by default. To grant it, add `--allow-sensitive-data-access` to `.mcp.json`.138139### SAM Template Validation Hook140141This plugin includes a `PostToolUse` hook that runs `sam validate` automatically after any edit to `template.yaml` or `template.yml`. If validation fails, the error is returned as a system message so you can fix it immediately. The hook requires SAM CLI and `jq` to be installed; if either is missing, validation is skipped with a system message. Users can disable it via `/hooks`.142143**Verify**: Run `jq --version`144145## Language selection146147Default: TypeScript148149Override syntax:150151- "use Python" → Generate Python code152- "use JavaScript" → Generate JavaScript code153154When not specified, ALWAYS use TypeScript155156## IaC framework selection157158Default: CDK159160Override syntax:161162- "use CloudFormation" → Generate YAML templates163- "use SAM" → Generate YAML templates164165When not specified, ALWAYS use CDK166167### Serverless MCP Server Unavailable168169- Inform user: "AWS Serverless MCP not responding"170- Ask: "Proceed without MCP support?"171- DO NOT continue without user confirmation172173## Resources174175- [AWS SAM Documentation](https://docs.aws.amazon.com/serverless-application-model/)176- [AWS Lambda Documentation](https://docs.aws.amazon.com/lambda/)177- [AWS Lambda Powertools](https://docs.aws.amazon.com/powertools/)178- [AWS CDK Documentation](https://docs.aws.amazon.com/cdk/)179- [AWS Serverless MCP Server](https://github.com/awslabs/mcp/tree/main/src/aws-serverless-mcp-server)